|
247371
|
6.3 |
MEDIUM
Network
|
jenkins
|
vsphere
|
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapsh…
|
CWE-863
Incorrect Authorization
|
CVE-2018-1000152
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247372
|
5.6 |
MEDIUM
Network
|
jenkins
|
vsphere
|
A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.
|
CWE-295
Improper Certificate Validation
|
CVE-2018-1000151
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247373
|
3.3 |
LOW
Local
|
jenkins
|
reverse_proxy_auth
|
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system acce…
|
CWE-200
Information Exposure
|
CVE-2018-1000150
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247374
|
5.6 |
MEDIUM
Network
|
jenkins
|
ansible
|
A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleCon…
|
NVD-CWE-noinfo
|
CVE-2018-1000149
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247375
|
6.5 |
MEDIUM
Network
|
jenkins
|
copy_to_slave
|
An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jo…
|
CWE-200
Information Exposure
|
CVE-2018-1000148
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247376
|
6.5 |
MEDIUM
Network
|
perforce
|
perforce
|
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to o…
|
CWE-200
Information Exposure
|
CVE-2018-1000147
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247377
|
8.8 |
HIGH
Network
|
jenkins
|
liquibase_runner
|
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the…
|
NVD-CWE-noinfo
|
CVE-2018-1000146
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247378
|
6.5 |
MEDIUM
Network
|
jenkins
|
perforce
|
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to …
|
CWE-200
Information Exposure
|
CVE-2018-1000145
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247379
|
6.1 |
MEDIUM
Network
|
jenkins
|
cucumber_living_documentation
|
A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000144
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247380
|
6.7 |
MEDIUM
Local
|
jenkins
|
github_pull_request_builder
|
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system acce…
|
CWE-200
Information Exposure
|
CVE-2018-1000143
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|